SAP CMC Promotion Management Internal Network Enumeration Vulnerability

Vulnerability

A vulnerability in SAP CMC Promotion Management allows authenticated attackers to enumerate internal network systems. This is achieved by sending crafted requests during job source configuration and analyzing the response times for different IP addresses and ports. Successful exploitation could lead to information disclosure, as valid network endpoints can be inferred from the response data. The vulnerability does not affect the application's integrity or availability.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure by allowing attackers to enumerate valid network endpoints.

Remediation

Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP Security Patch Day Bulletin. Instructions for accessing SAP Security Notes can be found on the SAP Security Notes FAQs page.

Added: Jul 8, 2025, 1:47 AM
Updated: Jul 8, 2025, 1:47 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.